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6 FEB 1978 
MEMORANDUM FOR: Director of Logistics 
FROM: Robert W. Gambino 
Director of Security 
SUBJECT: Security Violations Occurring at CIA 


Funded Contractor Facilities -- 
Definition of and Reporting Procedures (U/AIUO) 


1. (S) During security audits conducted at Agency- 
funded and non-Agency-funded contractors as a result of 
the Boyce/Lee Case, it has become apparent that some 
contractors have not been reporting security violations to 
Headquarters. It is recognized that such reports have not 
been required in the past with respect to collateral 
Classified contracts, and that it was only in the SCI area 
that reporting of security violations was mandatory. Many 
contractors have adopted the policy of reporting only 
violations which have, in their judgment, resulted in 
compromise or which they felt could potentially result in 
compromise. They have not uniformly reported other matters 
such as open safes or unsecured classified material found 
by guards, preferring to regard them simply as securtty 
"discrepancies" rather than as violations. 


2. (U/AIUO) The Director of Central Intelligence has 
expressed concern regarding this situation and agrees that 
such a lack of reporting is unacceptable. The following 
policy will, therefore, apply with regard to all contracts 
under the cognizance of the Central Intelligence Agency: 


(U/AIUO) "SECURITY VIOLATION: Any breach of 
security regulations, requirements, procedures or 
guides by an individual which subjects classified 
or sensitive material or information to compromise 
to unauthorized persons, or which places it in 
jeopardy where a compromise could result, constitutes 
a reportable security violation. Such a breach 
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includes both acts of omission such as failure 

to properly secure classified or sensitive material, 
and acts of commission such as discussion of 
Classified or sensitive information over nonsecure 
telephone circuits. The information and materials 
referred to in this definition comprise Collateral 
classified, SCI classified, and those materials 

and information which are sensitive because they 
involve intelligence sources and metheds." 


3. (U/AIUO) It is requested that you disseminate the 
definition as shown above to all of your contractors. 


4. (U/AIUO) Along with the definition, please forward 
a copy of the attached Securify Violation Report Form. It 
may be reproduced locally by each contractor as necessary. 
Please inform your contractors that the Security Violation 
Report Forms, when filled in, are to be classified SECRET 
1f they relate to SCI contracts, and CONFIDENTIAL if they 
relate to Collateral-type contracts. The contractor is to 
submit these forms in duplicate to the Cognizant Headquarters 
Security Officer (CHSO). The CHSO will maintain one copy 
in Office of Logistics files as a record of security violations 
pertaining to that particular contract for review during contract 
award fee negotiations. The CHSO will send the second copy to 
the Office of Security for inclusion in the individual's 
security file. Full Program names should not be used in reporting 
SCI violations on this Security Violation Report Form because 
the forms will ultimately be stored in a noncompartmented area. 
If it is necessary for the contractor to report SCI detallis 
of a violation, the facts should be separately stated in an 
attachment which will be detached upon receipt at Headquarters 
and maintained under SCI control. 


5. (U/AIUO) It is recognized that the Office of 
Communications has already established procedures under which 
contractors report certain types of COMSEC violations to 
Headquarters. This new procedure is a supplementary requirement. 


6. (U/AIUD) Please advise this Office when the actions 
in paragraphs 3 and 4 have been accomplished. 
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